FROID NR-1/ISO-45003 — the operating cycle

How it works, from setup to proof of effectiveness

We publish the whole route, with no sign-up and nothing held back. The process below is what a psychosocial risk regime requires — there is no secret in it. What is hard, and what almost nobody delivers, is the last stage.

First, a clarification that prevents a misunderstanding: in the psychosocial module there is no session. Nobody is interviewed, nobody turns on a camera and no FROID professional walks into your company. The worker receives a link, answers an anonymous questionnaire in about ten minutes, and that is it. Voice and face analysis is FROID's other product, used by health professionals in clinical care — and the employer never has access to it.

The seven stages — and the detour when the cycle does not close

Structure

Setup and structure

The employer draws its own structure in FROID: sites, departments and how many people are in each. This is not paperwork — it defines which result breakdowns will be possible later. A department that is too small will not produce a result of its own, and it is better to know that now.

Prepare

Preparing the campaign

This is where the three things only your company has come in: the real support channel — the phone line or service a worker turns to if they are not well —, the purpose notice and the grading criteria. If you already use a 5×5 matrix for chemical risk, FROID uses the same one for psychosocial risk, because a risk-management programme has to stay coherent across every hazard in it.

Hard stop: with no support channel on file, the system refuses to open the campaign. Asking someone how they are and having nowhere to refer them is worse than not asking.
Collect

Collection

Workers receive a single-use link that does not record who the person is. There are about 39 questions about working conditions — workload, autonomy, role clarity, support, harassment, isolation. Not one question about symptoms, mood or diagnosis: the instrument assesses the environment, not the person.

Hard stop: throughout collection the employer sees absolutely nothing — no partial figure, no percentage by department. The reason is mathematical: if the dashboard shows the result at 30 respondents and then at 31, the difference between the two screens reveals the thirty-first person's answer.
Close and review

Result

The campaign closes and only then does the dashboard open. The employer sees, for example: “Maintenance, 68 respondents, Excessive Demands dimension at high risk”. It never sees an individual answer, because the database does not allow that query to anyone — not to the company's owner, and not to us.

Hard stop: a breakdown with fewer respondents than the floor simply does not appear. Anonymity beats curiosity, including when that frustrates the client.
Document

Inventory, ergonomic assessment and action plan

Here is what the law actually demands. The psychosocial risk inventory with the nine mandatory fields, the preliminary ergonomic assessment and the action plan: what the employer will do about each identified risk, with a deadline and an owner. They come out as documents that go into the risk-management programme.

Implement and monitor

Implementation

The measures belong to the employer. FROID keeps the recorded criteria, the evidence and the dates — so that when somebody asks, there is a trail rather than a recollection.

Afterwards

The proof of effectiveness

A new campaign, the same instrument, the same department. FROID compares the two moments and says whether the measure worked — with the effect size and the confidence interval, not with a green arrow.

And it says “no change” when the data does not support an improvement, even when the raw number looks good. A gain that the statistics will not carry is exactly what an opposing expert takes apart.

If it fails

The measure did not work — and the rule already says what to do

It happens, and it is not a supplier failure. The Brazilian rule anticipates the situation: a measure whose monitoring indicates ineffectiveness must be corrected, the risk does not drop in the grading while there is no result, and the review of the assessment is brought forward. The cycle starts again, one step higher in the hierarchy of controls.

See the full procedure, clause by clause

Why nobody can know who answered what

This is the first question any works council, any union and any worker about to report harassment will ask. The answer is not a promise of conduct — it is a property of the architecture, and it fits into four verifiable facts.

1. The knowledge is split between two hands from the start

To dispatch the invitations, your company receives the pairing between payroll number and link. FROID does not keep that pairing. On our side there is only a pseudonym, derived from the payroll number by HMAC-SHA256 with a key held on the server — without it, nobody can rebuild the table from a payroll list they already hold. Alone, neither party can link person to answer.

2. The application cannot read an answer

The answer tables carry no read policy, and the database role the application uses had every privilege over them revoked. It can write an answer and it can request an aggregate — it cannot read one back. The only way out is a function that sums the results and clamps the cohort floor inside SQL itself, so the guarantee survives even a programming error in the layer above.

3. When collection closes, the link is erased

During collection a link exists between the invitation and the answer — it is what prevents the same link from being used twice. The moment the campaign is closed, and in the same commit, that link is erased from the database. From then on the data that would allow the pairing ceases to exist: there is nothing to recover, not even under a court order, because there is nothing to hand over. Every closing records in the audit trail how many links were severed.

4. Results only ever appear aggregated

No breakdown is published below the cohort floor, and insufficient breakdowns are declared insufficient rather than disappearing from the screen — suppressing hides, declaring documents. Results are also not released during collection, because the difference between two moments would reveal the answer of whoever came in between.

What we do not promise. Your company distributes the links and therefore knows whether you answered — never what you answered. We say so plainly in the invitation header, and not as a formality: promising anonymity of participation as well would be the one overstatement capable of destroying the credibility of everything we do guarantee.

The hazard list from the 2025 regulator's guide

The Brazilian labour ministry's Guide to Work-Related Psychosocial Risk Factors publishes this list of hazards and their possible consequences. It is indicative and not exhaustive: inspection assesses the coherence of the identification process, not literal adherence to the list. Your company can add hazards specific to its sector and set aside those that do not apply, as long as it documents the technical justification. The categories map closely onto the ones ISO 45003 describes, which is why the list is useful well beyond the jurisdiction that published it.

Hazard (psychosocial risk factor)Possible injury or harm
Management and work organisation
Poorly managed organisational changeMental disorder; work-related musculoskeletal disorder
Low role or task clarityMental disorder
Low reward and recognitionMental disorder
Lack of support at workMental disorder
Low job control / lack of autonomyMental disorder; work-related musculoskeletal disorder
Low organisational justiceMental disorder
Load and demand
Excessive job demands (overload)Mental disorder; work-related musculoskeletal disorder
Low job demand (underload)Mental disorder
Relationships and violence
Harassment of any kind at workMental disorder
Violent or traumatic eventsMental disorder
Poor workplace relationshipsMental disorder
Environment and working arrangement
Remote and isolated workMental disorder; fatigue
Work in conditions of difficult communicationMental disorder

Remote, hybrid and teleworking arrangements are inside the assessment. The employer adapts the strategy to the context — it does not leave those workers out.

What is the same in every company, and what changes

The same for everyoneChanges at each company
The 13 dimensions and the items of the instrument The structure of sites and departments
The minimum respondent floor The support channel, which belongs to the employer
Nothing comes out while collection is open The context of the questions by economic sector
The nine fields of the inventory The grading matrix, if you already use one

The instrument never changes between clients, and that is deliberate. If each company had its own, nothing would be comparable over time or between cohorts — and the proof of effectiveness, which depends on measuring the same thing twice, would cease to exist.

And what if the second assessment fails?

The employer measured, found risk, changed processes, measured again — and the index is still bad. It is the situation that frightens buyers most, and the one that produces the wrong question most often: “how do I make the number improve?”

The rule already answers. And the answer is not to explain it away: it is to correct the measure.

“Prevention measures must be corrected when the data obtained in monitoring indicates ineffectiveness in their performance.”

Brazilian rule NR-1, clause 1.5.5.3.2.1 — translated from the Portuguese original

That clause is not isolated — it sits inside a mechanism the rule closes completely:

Clause What it determines Effect when the second assessment fails
1.5.4.4.5.3 Probability must take into account the demands of the activity and the effectiveness of the prevention measures implemented. The risk does not drop. It would only drop if the measure had worked — and it did not. The grading stays high.
1.5.5.3.2 The performance of the measures must be monitored in a planned way. Monitoring is mandatory. It is what revealed the ineffectiveness — the second assessment is the rule working, not the opposite.
1.5.5.3.2.1 A measure whose monitoring indicates ineffectiveness must be corrected. A new obligation is born: correct it. Repeating the same measure under another name does not correct anything.
1.4.1, “g” Hierarchy of controls: eliminate the risk factor; collective protection measures; administrative or work-organisation measures; and, last, personal protection. Correcting normally means moving up one step. If a training course failed (administrative), the expected answer is not another training course — it is changing the organisation of work or eliminating the factor.
1.5.5.2.2 Measures must have a schedule, owners, forms of monitoring and verification of results. The corrected measure enters a new action plan, with a deadline and a named owner.
1.5.5.2.1.1 The number of workers possibly affected raises the priority of the action. A risk that resisted the first intervention and reaches many people moves up the queue, not down.
1.5.4.4.6 “a” and “c” Assessment is a continuous process, reviewed every two years — or sooner, among other triggers, after implementing measures (residual risks) and when inadequacies, insufficiencies or ineffectiveness are identified. Failure brings the mandatory review forward. You cannot wait out the two-year cycle.
1.5.7.3.2 and 1.5.7.3.3.1 Risk inventory with the nine fields, and history kept for 20 years. The measure that failed and the correction adopted stay on the record. That is memory, and memory is what inspectors and courts read.

In practical order, when the second assessment fails:

  1. Record the ineffectiveness. Do not dress it up, do not reclassify, do not switch instruments to get a different number.
  2. Keep the grading high. Risk does not drop through effort; it drops through result.
  3. Correct the measure, moving up the hierarchy of controls.
  4. Open a new action plan with a schedule, an owner and a verification method.
  5. Re-prioritise considering how many workers are exposed.
  6. Bring the review of the risk assessment forward.
  7. Measure again. The cycle does not close until the measure demonstrates an effect.
Why this is an advantage, not a problem. A company that does not measure can claim the measure worked, and nobody contests it — until a citation, an expert examination or a civil action. A company that measures is left with an uncomfortable result, but also with proof that it monitored, identified the failure and corrected it. That is exactly what the monitoring clause requires and what almost nobody can produce.

FROID handles this in the calculation engine, not in the wording of the report: a measure classified as ineffective grants no reduction of probability in the grading. It cannot lower the risk on paper while it fails in practice. And the direction of an effect is only declared after it survives the noise of its own cohort, at a 95% confidence interval — so that “improved” means improved, and not sampling variation.

The clauses above are cited from the text of the Brazilian rule NR-1 as amended by Ministerial Order MTE no. 1,419/2024, and translated from the Portuguese; the wording that carries legal weight is the Portuguese one. This page describes the procedure set out in that rule and does not constitute legal advice: analysis of the specific case belongs to the organisation's counsel.

Is your company big enough for this?

The two gates that decide it — anonymity and representativeness — are explained in full in When the data is not enough, including what happens to a breakdown that does not clear them.

A result is only released above a respondent floor, which is why small companies sometimes cannot get a result by department. It is worth finding out before signing, not after.

In Brazil, exemption from preparing a PGR depends on the conditions of NR-1, not company size alone. Confirm eligibility with your occupational safety adviser. The FROID ergonomic assessment workflow is independent of questionnaire result publication.

Check my company's readiness Ask a question about the rule

What FROID does not do, under any circumstance: it does not issue a diagnosis, does not classify a worker into a risk band, does not hand an individual answer to the employer and is not a validated psychometric instrument. It measures working conditions and produces the documents the regulation requires.